First published: Fri Oct 21 2011(Updated: )
Cross-site scripting (XSS) vulnerability in ocsinventory in OCS Inventory NG 2.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OCS Inventory NG | =1.0 | |
OCS Inventory NG | =1.02 | |
OCS Inventory NG | =1.0-beta | |
OCS Inventory NG | =1.01 | |
OCS Inventory NG | <=2.0.1 | |
OCS Inventory NG | =1.0-rc3-1 | |
OCS Inventory NG | =1.02-rc2 | |
OCS Inventory NG | =1.02-rc1 | |
OCS Inventory NG | =1.02.1 | |
OCS Inventory NG | =1.0-rc1 | |
OCS Inventory NG | =1.02-rc3 | |
OCS Inventory NG | =1.0-rc3 | |
OCS Inventory NG | =1.0-rc2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-4024 is categorized as a high-severity vulnerability due to its potential for remote exploitation through cross-site scripting.
To mitigate CVE-2011-4024, upgrade OCS Inventory NG to version 2.0.2 or later, which addresses the vulnerability.
CVE-2011-4024 affects OCS Inventory NG versions up to and including 2.0.1.
Yes, exploitations of CVE-2011-4024 can allow attackers to inject malicious scripts, potentially leading to data theft.
CVE-2011-4024 can target users of the affected versions of OCS Inventory NG who access compromised web pages.